AD domain controller using unsecure encryption type

Domain controllers using outdated or insecure encryption types expose sensitive data to attackers, enabling privilege escalation and credential access through Kerberos protocol exploitation.
Entra ID tenant without policy to show application name context in Microsoft Authenticator notifications

Entra ID tenant without policy to show application name context in Microsoft Authenticator notifications exposes users to potential account compromise through authentication requests, enabling attackers to exploit this via misleading or generic names.
AD domain with non-default permissions on krbtgt account

A domain with non-default permissions on the krbtgt account exposes attackers to creating a Golden Ticket, granting unauthorized Kerberos authentication.
AD domain accounts with password not required

Attackers can exploit AD domain accounts with password not required for unauthorized access, potentially leading to credential exposure and misuse.
AD domain account with Kerberos pre-authentication disabled

A domain account without Kerberos pre-authentication protection exposes attackers to offline password cracking opportunities.
Microsoft Entra app with client secrets

A Microsoft Entra app with client secrets increases exposure due to potential secret disclosure and enables attackers to access permissions granted to the service principal.
Microsoft Entra tenant with device settings allowing brute force attacks

A Windows device with disabled password attempt restrictions exposes attackers to repeated login attempts, increasing the risk of successful access.
Microsoft Entra tenant allowing unsecure token persistence

A Microsoft Entra tenant allowing unsecure token persistence exposes administrators to unauthorized access through cached Primary Refresh Token (PRT) extraction, enabling attackers to bypass Multi-Factor Authentication (MFA).
Microsoft Entra tenant with unsecure Guest user access permissions

A Microsoft Entra tenant with unsecured Guest user access permissions exposes groups and users to unauthorized enumeration, expanding attacker reconnaissance capabilities.
Microsoft Entra tenant with security defaults not enabled

Attackers can use previously obtained credentials for legacy authentication due to a lack of multi-factor authentication and conditional access policy enforcement in an unsecured Microsoft Entra tenant.